nerdexam
Microsoft

SC-200 · Question #137

You have an Azure subscription that has Microsoft Defender for Cloud enabled. You have a virtual machine that runs Windows 10 and has the Log Analytics agent installed. You need to simulate an…

The correct answer is B. Copy and executable and rename the file as ASC_AlertTest_662jfi039N.exe. Microsoft's official method for testing that Microsoft Defender for Cloud (formerly Azure Security Center) alert generation is working correctly is to copy any executable file and rename it to 'ASC_AlertTest_662jfi039N.exe.' This specific filename is recognized by the Defender…

Submitted by packet_pusher· Apr 18, 2026Manage threat mitigation using Microsoft Defender for Cloud

Question

You have an Azure subscription that has Microsoft Defender for Cloud enabled. You have a virtual machine that runs Windows 10 and has the Log Analytics agent installed. You need to simulate an attack on the virtual machine that will generate an alert. What should you do first?

Options

  • ARun the Log Analytics Troubleshooting Tool.
  • BCopy and executable and rename the file as ASC_AlertTest_662jfi039N.exe.
  • CModify the settings of the Microsoft Monitoring Agent.
  • DRun the MMASetup executable and specify the -foo argument.

How the community answered

(53 responses)
  • A
    17% (9)
  • B
    72% (38)
  • C
    4% (2)
  • D
    8% (4)

Explanation

Microsoft's official method for testing that Microsoft Defender for Cloud (formerly Azure Security Center) alert generation is working correctly is to copy any executable file and rename it to 'ASC_AlertTest_662jfi039N.exe.' This specific filename is recognized by the Defender for Cloud detection engine and will trigger a test alert without causing actual harm. This step must be performed first-before any agent modifications-because the test validates the alert pipeline end-to-end. Running the Log Analytics Troubleshooting Tool or modifying MMA settings are diagnostic steps, not attack simulation steps.

Topics

#Defender for Cloud#Security Alerts#Attack Simulation#VM Security

Community Discussion

No community discussion yet for this question.

Full SC-200 Practice